Inventory
The AI on each machine
Assistants, agentic editors, local models like Ollama — plus disk encryption, firewall, antivirus and updates on each machine.
What the agent readsAI governance
A read-only agent maps the AI and security posture of each machine — the groundwork for ISO/IEC 42001, read at the source.
Sign in with your company’s Google account. Microsoft coming soon.
What we can’t see yet is written on this page.See the limits
01Shadow AI
Marketing uses one AI, legal another, IT a third. Which one runs on which machine, nobody can say.
Someone installed a model that runs on their own laptop. No agentless tool can see it.
A customer asks how you govern AI use. The honest answer is a spreadsheet and good intentions.
The auditor wants evidence the control worked in March. All you have is today’s screenshot.
02Why now
In Brazil, the data protection authority (ANPD) has set aside 20 enforcement actions on AI and emerging technologies for 2027.
Source: ANPD, Resolution CD/ANPD No. 30/2025 (2026–2027 Priority Topics Map)
51%
of CTOs, CIOs and CISOs can’t say for certain whether an AI-built internal tool has caused an incident.
Retool, The State of AI Governance in 2026 · 307 CTOs, CIOs and CISOs, May 2026
8%
describe their company’s governance of internal tools as strong.
Retool, The State of AI Governance in 2026 · 307 CTOs, CIOs and CISOs, May 2026
€35M or 7%
of worldwide turnover: the EU AI Act’s top fine, reserved for prohibited AI practices.
Regulation (EU) 2024/1689, Art. 99 · applicable since 2 August 2025
03The product
Inventory
Assistants, agentic editors, local models like Ollama — plus disk encryption, firewall, antivirus and updates on each machine.
What the agent readsISO/IEC 42001
Coverage: how much of the standard was assessed. Conformity: of that, how much passes. Unassessed never counts as failure.
Actions
Each failure becomes an action: owner, due date, fix. Accepted risk needs a reason and never counts as a pass.
Evidence
Every result joins a signed hash chain that any auditor can verify without taking our word for it.
Provenance04Provenance
April 2026
A US compliance startup valued at $300 million was removed from the Y Combinator directory after allegations that its reports were written before the evidence existed — the same passage in 493 of 494. The company denies it.
Sources: TechCrunch, 4 Apr 2026 · The Tech (MIT), 9 Apr 2026 · DeepDelver, 19 Mar 2026
Since then, the buying question has changed: where did each piece of evidence come from?
Every submission leaves the machine signed with the device’s own key. The data comes from it, not from us.
Each result carries the previous one’s hash and our signature. Alter one record and every later one breaks.
Any auditor recomputes the chain with the public key, no login needed. The answer is “intact” or the exact break.
Verify a dossier
Preview · coming soonIntact — the chain closes end to end
Verification can say no. That’s what makes the yes worth something.
The chain, the signature and public verification are not live yet. Until they are, nothing here is called signed proof.
05How it works
Illustrative screen. Fictional data.
Sign in with your company’s Google account, create the organization and invite your team with roles.
The screen generates one command with the key. Run it on the machine as an administrator: it enrolls right away.
The machine shows up the moment the agent installs — AI, encryption, antivirus, updates. Then a fresh read every six hours.
Each failure becomes an action with a deadline. The next reading confirms the fix. Signed proof is coming soon.
06Transparency
The same words as the Devices screen, inside the product.
07Declared limits
AI used on a device the company doesn’t manage is out of our reach. There, only internal policy covers it.
The agent sees programs, not websites. AI used in the browser — personal accounts included — doesn’t show up yet.
No Google Workspace, Microsoft 365 or AWS connectors yet. The agent runs on macOS and Windows.
Accredited certification bodies certify ISO/IEC 42001. We deliver the readings and, soon, the proof.
What no source verifies counts as not assessed: it lowers coverage, never conformity.
08MSP partners
09Questions
No. It reads the machine: name, serial number, operating system, disk encryption, firewall, antivirus, screen lock, Secure Boot, updates, installed software and which AI tools are present and running. Never file, e-mail or message content, the screen, the clipboard, sites visited or keystrokes — nor AI prompts or conversations. Full list above, same as in the product.
No. It blocks nothing, changes no settings and installs nothing but itself. It reads every six hours and signs each submission with the device’s own key. It doesn’t replace your antivirus or EDR — we’re not competing for that slot. Revoke a device on screen and it stops reporting right away.
Today: readings from macOS and Windows machines running the agent — AI installed and running, and security posture. ISO/IEC 42001 assessment, with guided questions on policy, roles, impact, suppliers, incidents and communication, is coming soon. Linux and cloud connectors aren’t there yet; Microsoft 365 is next.
No — and no software vendor can. Accredited certification bodies certify. Atesto’s job is different: read the machines all year and, soon, deliver proof your auditor verifies independently instead of requesting it by e-mail.
Because one score blends “we checked and it’s wrong” with “nobody has looked yet”, and each calls for the opposite action. Coverage says how much was assessed; conformity, how much of that passes. One failing machine fails the check — “almost all” isn’t an answer. A failed reading never becomes a failure. And you can redo the math by hand.
The evidence engine. Each result starts carrying the previous one’s hash and our signature; what we store goes into storage that refuses edits and deletions until retention ends, including by us; and public verification goes live. Until then, nothing in this product is called signed proof.
Pricing isn’t final yet. When it is, it goes on this page for anyone to see — no “contact sales” required. That part is already decided.
Today, one machine at a time: the same key works for the whole fleet, and each machine gets its own identity, which survives renames and reinstalls and can be revoked on screen without touching the others. The signed installer for GPO or RMM rollout is coming soon.
Create an account, install the agent and see what it finds. What we can’t see yet is written above.